OIDC Endpoints Reference

Keycloak exposes a set of standard OpenID Connect and OAuth 2.0 endpoints for each Realm. All endpoints are discoverable via the OIDC discovery document.

Discovery Endpoint

GET https://<keycloak-host>/realms/<realm>/.well-known/openid-configuration

Returns a JSON document listing all available endpoints, supported scopes, grant types, signing algorithms, and other provider metadata.

Core Endpoints

EndpointURLDescription
Authorization/realms/<realm>/protocol/openid-connect/authInitiates user authentication. Supports response_type: code, id_token, token.
Token/realms/<realm>/protocol/openid-connect/tokenExchanges authorization codes, refresh tokens, or client credentials for tokens.
UserInfo/realms/<realm>/protocol/openid-connect/userinfoReturns claims about the authenticated user. Requires a valid access token.
JWKS/realms/<realm>/protocol/openid-connect/certsReturns the public keys used to verify token signatures (JWK Set format).
End Session (Logout)/realms/<realm>/protocol/openid-connect/logoutTerminates the user's SSO session. Supports id_token_hint and post_logout_redirect_uri.
Token Introspection/realms/<realm>/protocol/openid-connect/token/introspectReturns the active/inactive status and claims of a token. Requires client authentication.
Token Revocation/realms/<realm>/protocol/openid-connect/revokeRevokes a refresh token or access token. Requires client authentication.

Registration and Management Endpoints

EndpointURLDescription
Dynamic Client Registration/realms/<realm>/clients-registrations/openid-connectOIDC Dynamic Client Registration endpoint. Requires an initial access token or valid bearer token.
Client Registration (Keycloak format)/realms/<realm>/clients-registrations/defaultKeycloak-specific client registration using Keycloak client representation format.

Device and Backchannel Endpoints

EndpointURLDescription
Device Authorization/realms/<realm>/protocol/openid-connect/auth/deviceInitiates the OAuth 2.0 Device Authorization Grant for input-constrained devices.
Backchannel Authentication (CIBA)/realms/<realm>/protocol/openid-connect/ext/ciba/authInitiates Client Initiated Backchannel Authentication.

SAML Endpoints

EndpointURLDescription
SAML Descriptor/realms/<realm>/protocol/saml/descriptorReturns the IdP SAML metadata document (Entity Descriptor).
SAML SSO (Redirect)/realms/<realm>/protocol/samlSAML Single Sign-On endpoint (HTTP-Redirect and HTTP-POST bindings).

Admin REST API

EndpointURLDescription
Admin API Base/admin/realms/<realm>Base URL for the Keycloak Admin REST API. See Admin REST API.

Token Endpoint Authentication Methods

When calling the token endpoint, clients authenticate using one of:

MethodDescription
client_secret_postClient ID and secret sent as POST body parameters
client_secret_basicClient ID and secret sent via HTTP Basic Authentication header
client_secret_jwtClient authenticates with a JWT signed using the client secret (HMAC)
private_key_jwtClient authenticates with a JWT signed using a private key (RSA/EC)
noneNo client authentication (public clients, must use PKCE)

Supported Scopes

ScopeClaims Included
openidsub (required for OIDC)
profilename, family_name, given_name, preferred_username, locale
emailemail, email_verified
addressaddress
phonephone_number, phone_number_verified
rolesrealm_access.roles, resource_access.<client>.roles
microprofile-jwtgroups, upn
offline_accessRequests a refresh token valid for offline access